pulumi

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install path is relatively legitimate, but the skill’s actual behavior is a Membrane integration more than a direct Pulumi integration. Its core data flow proxies Pulumi auth and API traffic through Membrane, which is broader and riskier than the stated Pulumi-only purpose.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpulumi%2F@af43304974faec82c43312fb333009dca7339d88
Security Audit — socket — pulumi